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Summary 

Cybersecurity vulnerabilities challenge governments, businesses, and individuals worldwide. 
Attacks have been initiated against individuals, corporations, and countries. Targets have included 
government networks, companies, and political organizations, depending upon whether the 
attacker was seeking military intelligence, conducting diplomatic or industrial espionage, 
engaging in cybercrime, or intimidating political activists. In addition, national borders mean 
little or nothing to cyberattackers, and attributing an attack to a specific location can be difficult, 
which may make responding problematic. 

Despite many recommendations made over the past decade, most major legislative provisions 
relating to cybersecurity had been enacted prior to 2002. However, on December 18, 2014, in the 
last days of the 1 13 th Congress, five cybersecurity bills were signed by the President. These bills 
change federal cybersecurity programs in a number of ways: 

• codifying the role of the National Institute of Standards and Technology (NIST) 
in developing a “voluntary, industry-led set of standards” to reduce cyber risk; 

• codifying the Department of Homeland Security’s (DHS’s) National 
Cybersecurity and Communications Integration Center as a hub for interactions 
with the private sector; 

• updating the Federal Information Security Management Act (FISMA) by 
requiring the Office of Management and Budget (OMB) to “eliminate ... 
inefficient and wasteful reports”; and 

• requiring DHS to develop a “comprehensive workforce strategy” within a year 
and giving DHS new authorities for cybersecurity hiring. 

In April 2011, the Obama Administration sent Congress legislative proposals that would have 
given the federal government new authority to ensure that corporations owning assets most 
critical to the nation’s security and economic prosperity adequately addressed risks posed by 
cybersecurity threats. This report provides links to cybersecurity legislation in the 1 12 th , 1 13 th , 
and 114 th Congresses. 

• 114 th Congress Legislation, House, Table 1 

• 114 th Congress Legislation, Senate, Table 2 

• 1 13 th Congress, Major Legislation, Table 3 and Table 4 

• 1 12 th Congress, Major Legislation, Table 5 and Table 7 

• 112 th Congress, Senate Floor Debate: S. 3414, Table 6 

• 1 12 th Congress, House Floor Debate: H.R. 3523, Table 8 

Congress has held cybersecurity hearings every year since 2001. This report also provides links to 
cybersecurity-related committee hearings in the 112 th , 113 th , and 114 th Congresses. 

• 114 th Congress, Senate Hearings, Table 9 and Table 10 

• 114 th Congress, House Hearings, Table 11 and Table 12 

• 113 th Congress, House Hearings, Table 14 and Table 15 

• 113 th Congress, House Committee Markups, Table 16 

• 113 th Congress, Senate Hearings, Table 17 and Table 19 

• 1 13 th Congress, Other Hearings, Table 18 and Table 20 
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• 1 12 th Congress, House Hearings, Table 21 and Table 22 

• 1 12 th Congress, House Markups, Table 23 

• 1 12 th Congress, Senate Hearings, Table 24 and Table 25 

• 1 12 th Congress, Congressional Committee Investigative Reports, Table 26 

On April 22, 2015, the House passed H.R. 1560, which will provide liability protection to 
companies that share cyber threat information with the government and other companies so long 
as personal information is removed before the sharing of such information. On April 23, 2015, the 
House passed H.R. 1731, which will encourage information sharing with the Department of 
Homeland Security by protecting entities from civil liabilities. 

On October 27, 2015, the Senate passed S. 754, the Cybersecurity Infonnation Sharing Act of 
2015 (C1SA), by a vote of 74-21 (Roll call vote 291). The House approved companion legislation 
in April, so the cybersecurity measure is now on track to reach President Obama's desk and be 
signed into law, once a conference report is negotiated. C1SA attempts to open up communication 
channels between industry and federal agencies by offering legal immunity to companies that 
share data with the government. For more information on what is covered in the Senate bill, see 
CRS Legal Sidebar WSLG1429, Senate Passes Cybersecurity Information Sharing Bill -What’s 
Next?, by Andrew Nolan. 

For a comparison of House and Senate information-sharing legislation in the 1 14 th Congress, see 
CRS Report R44069, Cybersecurity and Information Sharing: Comparison of House and Senate 
Bills in the 114th Congress, by Eric A. Fischer and Stephanie M. Logan. 

For a side-by-side comparison of cybersecurity and infonnation legislation in the 1 14 th Congress, 
see CRS Report R43996, Cybersecurity and Information Sharing: Comparison of H.R. 1560 and 
H.R. 1731 as Passed by the House, by Eric A. Fischer and Stephanie M. Logan. 

For an economic analysis of information-sharing legislation, see CRS Report R43821, Legislation 
to Facilitate Cybersecurity Information Sharing: Economic Analysis, by N. Eric Weiss. 

For a discussion of selected legislative proposals in the 1 12 th and 1 13 th Congresses, see CRS 
Report R42114, Federal Laws Relating to Cybersecurity: Overview of Major Issues, Current 
Laws, and Proposed Legislation, by Eric A. Fischer. 

Executive orders authorize the President to manage federal government operations. Presidential 
directives pertain to all aspects of U.S. national security policy as authorized by the President. 

This report provides a list of executive orders and presidential directives pertaining to infonnation 
and computer security. 

• Executive Orders and Presidential Directives, Table 27 

For a selected list of authoritative reports and resources on cybersecurity, see CRS Report 
R42507, Cyber security: Authoritative Reports and Resources, by Topic, by Rita Tehan. For 
selected cybersecurity data, statistics, and glossaries, see CRS Report R43310, Cybersecurity: 
Data, Statistics, and Glossaries, by Rita Tehan. 
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